Adapting Matt Pocock's grill-with-docs skill to create a Threat Modeling skillMay 23, 2026·5 min read
Security Reviews of Enterprise AI Systems in 2026Lessons from Recent Disclosures and Real-World ReviewsAug 25, 2026·16 min read
Pipeline Security and Supply Chain Risk: Closing the Gap Between AppSec and CloudSecMay 19, 2026·12 min read
Attacking Kubernetes: Offensive Recon and Attack Path Analysis with CDK, Kubehound, and KubescapePart 1 - Lab setup, attacker simulation, and finding exploitable misconfigurationsMay 14, 2026·12 min read
Securing AI Models: Understanding Threats and Testing StrategiesSecuring AI: Microsoft Shares Key Research FindingsAug 24, 2025·5 min read
A Comprehensive Guide to the EU Cyber Resilience Act (CRA) for ManufacturersEU Cyber Resilience Act Explained by a Cybersecurity ProfessionalAug 23, 2025·10 min read
AppSec Is Drowning in Noise — What Are We Actually Protecting?Introduction Application security was supposed to be a safety net. Lately, it feels more like quicksand. Modern AppSec teams are swamped by an endless stream of alerts. The report found on thehackernews.com prompted me to think about this issue (http...Jun 2, 2025·4 min read
Threat Modeling: A Complete How-To GuideIdentify and manage security risks in software architectureDec 14, 2024·14 min read
A Guide to Strengthening Infrastructure as Code (IaC) SecurityIntroduction Infrastructure as code (IaC), also known as software-defined infrastructure, allows the configuration and deployment of infrastructure components faster with consistency by allowing them to be defined as a code and also enables repeatabl...Dec 6, 2024·4 min read